The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
8,323 vulnerabilities with CWE-862
CVE-2025-66109
MEDIUM
Cart Weight for WooCommerce <1.9.11 - RCE
CVSS 5.3
CVE-2025-66108
MEDIUM
Merlot Digital TNC Toolbox: Web Performance <2.0.5 - RCE
CVSS 4.3
CVE-2025-66107
MEDIUM
Scott Paterson Subscriptions & Memberships for PayPal <1.1.8 - Info...
CVSS 5.3
CVE-2025-66106
MEDIUM
Essential Plugin Featured Post Creative <1.5.5 - Info Disclosure
CVSS 4.3
CVE-2025-66101
MEDIUM
Sabuj Kundu CBX Bookmark & Favorite <= 2.0.1 - Info Disclosure
CVSS 4.3
CVE-2025-66099
MEDIUM
ThemeAtelier Chat Help <3.1.3 - RCE
CVSS 5.3
CVE-2025-66096
MEDIUM
Tableberg Table Block <0.7 - Auth Bypass
CVSS 4.3
CVE-2025-66089
MEDIUM
WebToffee Product Feed <2.3.1 - RCE
CVSS 4.3
CVE-2025-66087
MEDIUM
PropertyHive <2.1.12 - Info Disclosure
CVSS 4.3
CVE-2025-66086
MEDIUM
Cozy Vision SMS Alert Order Notifications <= 3.8.8 - Missing Authorization
CVSS 5.3
CVE-2025-66085
MEDIUM
Arconix Shortcodes <= 2.1.18 - Missing Authorization
CVSS 4.3
CVE-2025-66084
MEDIUM
Shahjahan Jewel FluentCommunity <2.0.0 - Info Disclosure
CVSS 4.3
CVE-2025-66083
MEDIUM
WpEvently <= 5.0.4 - Missing Authorization
CVSS 5.3
CVE-2025-66082
MEDIUM
WpEvently <= 5.0.4 - Missing Authorization
CVSS 5.3
CVE-2025-66079
MEDIUM
Jegstudio Gutenverse Form <2.2.1 - RCE
CVSS 6.5
CVE-2025-66077
MEDIUM
wpWax Legal Pages <1.4.6 - Info Disclosure
CVSS 5.3
CVE-2025-66075
MEDIUM
WP Legal Pages WP Cookie Notice <4.0.3 - RCE
CVSS 4.3
CVE-2025-66072
MEDIUM
UsersWP <= 1.2.47 - Missing Authorization
CVSS 5.3
CVE-2025-66071
MEDIUM
Custom Order Numbers for WooCommerce <1.11.0 - Info Disclosure
CVSS 5.3
CVE-2025-66069
MEDIUM
Themeisle PPOM for WooCommerce <34 - RCE
CVSS 4.3
CVE-2025-66065
MEDIUM
Jegstudio Gutenverse <= 3.2.1 - Missing Authorization
CVSS 6.5
CVE-2025-66063
MEDIUM
WP Google Review Slider <= 17.4 - Missing Authorization
CVSS 5.4
CVE-2025-66060
MEDIUM
Seriously Simple Podcasting <3.13.0 - Info Disclosure
CVSS 5.3
CVE-2025-10054
MEDIUM
Elula Wsdesk < 3.3.2 - Missing Authorization
CVSS 4.3
CVE-2025-13149
MEDIUM
Schedule Post Changes With PublishPress Future: Unpublish, Delete, ...
CVSS 4.3
Details
Vulnerabilities
8,323
Exploit Likelihood
High